Blacklight Toolkit Finds Codex, Claude Code, and Cursor Artifacts Exposing Tokens and Session Data
Brief
SpecterOps has released Blacklight, an open-source toolkit that identifies local artifacts from AI coding agents like Codex, Claude Code, Cursor, and Antigravity CLI, which can expose authentication data , session history, project details, and connected services.
AI agents are increasingly used to write code, troubleshoot problems, run commands, inspect repositories, and interact with cloud resources.
These tools improve productivity, but they also create a new endpoint security concern. Their local files may contain sensitive information that attackers could use after gaining access to a workstation.
Blacklight helps authorized security teams understand this emerging exposure. Rather than immediately collecting every file, the toolkit first identifies installed AI agents.
It ranks the most useful artifacts for review.
